ArgusLeaf

Signal vs verdict

We report suspicion, not guilt.

A score above our alert threshold means a domain name looks statistically similar to something on your watch-list, and that similarity is unusual enough to warrant your attention. It does not mean:

  • The domain is actively phishing anyone
  • The domain was registered with intent to harm you
  • The domain owner has malicious intent

Many matches are legitimate: a competitor who includes your brand name in a keyword, a parked domain purchased years ago, a security researcher's test environment. We state this clearly in every alert we send.

Thresholds

Three tiers.

Score Delivery Meaning
≥ 90 Immediate email Strong match — review urgently
50–89 Daily digest Plausible match — review when convenient
20–49 Internal log only Weak signal — not delivered to you
< 20 Discarded Statistical noise

Thresholds are adjustable per tenant. High-risk sectors (banking, crypto) typically lower the immediate alert threshold to 80 to catch more borderline cases.

Accuracy

We expect false positives.

An automated system running at CT-log scale will produce false positives. Our goal is to keep the ratio low enough that alerts remain actionable — not to eliminate false positives by raising the threshold, which would also eliminate true positives.

If you consistently see false-positive domains matching a particular pattern, you can add those patterns to your suppress-list and we'll filter them before delivery. Suppression rules are tunable without changing your alert threshold.

Scope

What ArgusLeaf is not.

We are a detection system, not an investigation or remediation service. We don't:

  • Determine intent (criminal, civil, or innocent)
  • Perform active security testing of found domains
  • Contact domain owners on your behalf
  • Issue takedown notices
  • Provide legal opinions or advice

For takedown and legal action, contact an IP or trademark attorney, or use your registrar's abuse mechanism.

Sources

What we read.

  • Certificate Transparency logs via RFC 6962 tile streaming (primary source)
  • Newly registered domain feeds — CZDS zone files and public registrar APIs
  • Public phishing intelligence feeds — redistributable entries only; non-redistributable entries are suppressed and never shown to tenants
  • WHOIS / RDAP for registration date
  • Passive DNS for enrichment context

We do not use active port scanning, vulnerability databases, or dark-web sources.